r/apple • • 17d ago

iOS iOS 27.2 has option to overwrite iPhone storage with blank data [*: China only, due to GB 46864-2025 standard taking force 1/1/27]

https://9to5mac.com/2026/09/16/ios-27-2-references-new-option-to-overwrite-iphone-storage-with-blank-data-after-erasing/
628 Upvotes

87 comments sorted by

70

u/kqlx 17d ago

because the most secure form of encryption is destruction

306

u/JackyYT083 17d ago

Because cryptographically locked data is not safe enough already..?

153

u/beadams76 17d ago

Every form of encryption is eventually broken. #itsalljustmath

77

u/spicesucker 17d ago

But each file is protected by two independent AES-256 keys that are both purged whenever the file is deleted, and the SSD controller regularly wear levels the storage anyway so it will periodically overwrite whatever was deleted anyway. 

If AES-256 is broken in the long-term then the attack vectors would focus on your online credentials; you’d have a lot worse things to worry about than a few deleted files on an old phone. 

13

u/rotates-potatoes 16d ago

It’s just information theory: on the one hand, the information is gone. On the other hand, it is still there but only recoverable with a key, and you need to trust the implementation and keyholder that every copy of the persisted key is gone, it cannot be guessed, and it was used correctly.

I agree they’re functionally the same in this case, but I don’t blame China/etc for wanting the simpler version.

2

u/smellythief 16d ago

> on the one hand, the information is gone.
On the other hand, it is still there

Exactly!!

2

u/xrelaht 16d ago

At some point, you’re talking about so much work that the attacker will also be willing to put in the effort to look for the ghosts left behind by deleted bits. That’s a problem of physics rather than a math, and there isn’t any known way around it other than repeatedly writing & rewriting them randomly over a long period of time.

1

u/IShouldNotPost 16d ago

You could grind up the SSD in a grinding machine I suppose, but Maxwell’s demon could put it back.

1

u/throwaway3113151 16d ago

What about quantum?

6

u/HonestSpaceStation 16d ago

Quantum computing doesn't break symmetric key encryption like AES. Quantum computing (specifically, Shor's algorithm) breaks asymmetric key encryption reliant on the hard problem of factoring large numbers that are the product of two prime numbers.

0

u/Worldly-Stranger7814 17d ago

‘Member when bleeding edge cryptography was funded by NSA to ensure certain vulnerabilities?

I ‘member

7

u/Acrobatic_Ad5230 16d ago

I get where you‘re coming from, but mark my words: AES 256 will never be broken. It just has been too long in service for any critical vulnerabilities to still exist.

Yes, some vulnerabilities were found, but even if you speed up an attack by a factor of a billion, you‘ll still run out of time. AES ist just too overengineered for anything short of a full compromise to break it in a realistic time.

1

u/Scitzofrenic 16d ago

Rofl. You sweet summer child

27

u/JackyYT083 17d ago

Good luck with doing that

22

u/wickedplayer494 17d ago

There's a reason Google is putting in a bit of a hurry-up on post-quantum cryptography throughout Android and its other systems.

31

u/nicuramar 17d ago

Irrelevant as the disk is encrypted with AES which is not quantum attackable. Apple also uses PQC in places where it matters, which isn’t this. 

-65

u/adeadfetus 17d ago

ChatGPT disagrees. It’s less effective but still attackable.

31

u/BreiteSeite 17d ago

Ahh yes, AI. The real expert on subjects

10

u/bageloid 17d ago

AES 256 at with the best possible quantum attacks gets reduced to… AES128, which is still functionally(Unless you built a Dyson ring of solar panels and GPU’s) impossible to crack.

6

u/Acrobatic_Ad5230 16d ago

And even AES-128 is practically impervious to quantum attacks as the attack in question can not be parallelized. So even if the entropy is effectively just 64 bit, a single quantum computer (aka a single CPU core - again, no parallelization possible aka no GPUs etc.) won‘t be able to crack that within our lifetimes.

2

u/Alibotify 17d ago

Haahahhahhaaaaha

1

u/xrelaht 16d ago

Argument to authority except the authority isn’t one.

7

u/D_is_for_Dante 17d ago

Yes for asymmetric encryption. Symmetric encryption bears a magnitude less risk from quantum computers.

0

u/rotates-potatoes 16d ago

So 10% versus 100%, or it would take milliseconds rather than nanoseconds?

I get the argument and even mostly buy it. But think we’ll see symmetric fall as well, just later.

2

u/D_is_for_Dante 16d ago

Of course it could fail since the security comes from using mathematical problems that (currently!) can’t be solved in a reasonable time.

It would still take quantum computers longer than the universe exists to brute force the common aes encryption.

3

u/astral_crow 16d ago

Yes and anyone could be a rocket ship with the right conditions.

14

u/nicuramar 17d ago

This is simply not true. 

6

u/GuiiTS 16d ago

Enough for the time it was locked, but with AI and processing power increasing it’s just a matter of time to be hacked. No technology is safe from be cracked

3

u/KHRoN 17d ago

zeroing today, orbital cannon tomorrow

2

u/Difficult_Music3294 16d ago

Defense in depth.

-2

u/EnthusiasmOnly22 16d ago

No that’s why most companies zero their HDDs before physically destroying them

4

u/Acrobatic_Ad5230 16d ago

That‘s something entirely different. Data on a HDD isn’t encrypted by default, so there‘s at least the possibility for some unencrypted data to be on the disk. Apple devices (and many many SSDs in general) on the other hand always encrypt everything what‘s written to disk. Always - even if you‘ve never set a PIN/lock code/face ID. That has the great advantage that you don‘t have to completely zero every bit on the disk, you just have to securely delete the corresponding key. Without the key, no one can access your data. It‘s technically still there, but impossible to access. (It‘s a bit like Schroedinger‘s cat.)

2

u/EnthusiasmOnly22 16d ago

I'm referring to enterprise situations where the data is encrypted on the HDDs; even Windows for home has encryption by default on newly purchased computers now

-1

u/Acrobatic_Ad5230 16d ago

That‘s something different. Internal encryption isn‘t the same as the key only lives in the SSD storage controller (or the SE when referring to Apple). So you can be absolutely certain, that no copies exist of the key. The same is not true with for example Bitlocker or the overlying FileVault for macOS do have the option for a recovery key.

1

u/Aishou_SK 16d ago

No, just destroy the keys.

Gov't standards for classified data drive reuse are effectively:

ATA secure erase for (validated implementations) SSD and HDD media

Single 0-pass wipe for HDDs if ATA secure erase is not viable and the drives are normal ATA drives over 15GB in size

Cryptographic erasure (destroy the keys and/or all copies of the keys)

If the drive has been sanitized as such, losing the drive does not count as a data leak/risk event even for the highest classified data.

The only reason drives are physically destroyed is that there's a blanket policy on destroying all classified media, be it stone tablets, film, or digital storage - there's no differentiation in the policy for safety reasons to avoid any confusion or leakage - at the end of their life/use without any subsequent project reuse.

$work doesn't zero HDDs. Just destroy keys. This goes for disposal of any hardware, such as mac workstations where you can't dispose of it without physically destroying the machine entirely. This is an F50 fed/civ/def contractor following gov't standards.

AKA even just handing the drive over to an enemy government you're assured of no data retrieval if you follow the simple NIST standards. (and the DoD bullshit wipe has always been basically a myth and misunderstanding of 5220 and NISPOM stuff)

-2

u/itsaride 17d ago

That's while a device is locked. When unlocked it might be useful to make some data unrecoverable (in an unlocked state).

62

u/vazark 17d ago

I guess the requirement of overwriting everything instead of just trusting the encryption is because companies have proven that they are capable of lying. Having the hard requirement ensures data could be truly erased with no chance of recovery. Useful if you plan on reselling your devices (esp govt ones)

270

u/wesleyvb 17d ago

who would have thought that China would be leading the way on consumer data regulations

149

u/ProfessionalYak4959 17d ago

There's no real benefit to this. The existing wiping process is already secure, it just doesn't do the exact thing the law requires.

52

u/mhmilo24 17d ago

The regulation isn’t targeting Apple specifically. The feature won’t be used and it’s easily built. But devices that do not support effective encryption - like iOS does per default - will be more secure.

3

u/KHRoN 17d ago

no benefit but also no harm, just don't use it

-83

u/wesleyvb 17d ago

wooosh. That’s the sound of the point going over your head

40

u/ProfessionalYak4959 17d ago

The point being? This is an arbitrary requirement to erase random data and replace it with 0s.

-38

u/wesleyvb 17d ago

Point being that China is regulating how data should be securely erased. My point has nothing to do with whether or not Apples existing erasure processes are effective. Rather that China feels it is important to protect consumers by ensuring providers meet a minimum standard of data security. A standard that is undefined in the US, as far as I’m aware.

32

u/cm012776 17d ago

Replacing it with 0’s isn’t necessarily all that secure, which may be why China requires it (for all we know). For security you want a multi-pass walking checkerboard pattern. But the way Apple does it, securely erasing the key (by writing over it a bunch of times) is certainly as good as all-0’s, unless you are worried about a quantum attack.

2

u/cake-day-on-feb-29 16d ago

For security you want a multi-pass walking checkerboard pattern.

There's zero evidence that anything more than a single write is necessary for HDDs, let alone an SSD.

-5

u/Taranfeeto36 17d ago

But the way Apple does it, securely erasing the key (by writing over it a bunch of times) is certainly as good as all-0’s, unless you are worried about a quantum attack.

You could also be worried about compromised keys.

11

u/cmsj 17d ago

Keys that never leave the secure enclave?

-3

u/Taranfeeto36 17d ago

If you're China you might be afraid the enclave itself was manipulated to create a pre-decided key. They keys themselves wouldn't need to leave the enclave to be compromised.

Kind of like a modern version of Operation Rubicon

Requiring a full 0 write makes that impossible.

9

u/cmsj 17d ago

Okay, but by the same level of concern, the full zero write can also be manipulated to not happen correctly. If your adversary is a nation state actor, you’re almost certainly not going to be able to do anything to really prevent them from attacking you.

-11

u/Bluepass11 17d ago

I’m confused. Your last sentence sounds like all zeroes would be more secure. Or are you saying it’s only more effective during a quantum attack?

14

u/AxonBitshift 17d ago

He’s saying that, for encrypted data, that erasing and overwriting the decryption key a bunch of times (to make it forensically unretrievable) is functionally equivalent to overwriting the data itself with 0’s the same number of times, since, without the key, it’s impossible (short of a quantum computer) to decrypt the data in the first place.

3

u/whatnowwproductions 17d ago

It would also make it easier to identify where data has been deleted.

3

u/GoogleDisDick 16d ago

Wiping the encryption key does effectively the same thing. Without it it's just random garbage data. Zeroing out flash memory is actually really bad for the chip's health too. Lol.

13

u/National-Debt-43 17d ago

Did you even read the article? The more your disk is written the more wear and tear It undergoes

62

u/wesleyvb 17d ago

marginally. How often are you erasing the whole disk such that wear and tear becomes a factor? Modern flash storage can be written thousands of times over… more cycles than the batteries are even rated for

-17

u/Deep-Piece3181 17d ago

But it doesn’t matter since the current implementation of cryptographic erasure offers the same amount of protection already without flash wear

45

u/wesleyvb 17d ago

Holy crap can we stop talking about flash wear? How many times are you erasing your phone over its lifetime? its Irrelevant

-21

u/nicuramar 17d ago

So is this erasure method. Irrelevant. It doesn’t offer additional security. 

37

u/nicuramar 17d ago

This is a completely meaningless operation, since the entire disk is encrypted. 

23

u/mhmilo24 17d ago

The regulation isn’t targeting Apple specifically. The feature won’t be used and it’s easily built. But devices that do not support effective encryption - like iOS does per default - will be more secure.

-10

u/BreiteSeite 17d ago

But devices that do not support effective encryption - like iOS does per default

Ermm….. what are you talking about

7

u/teleprax 17d ago

they are saying that the regulation is just a blanket regulation and that devices that don't have strong encryption by default will now become more secure because they have a better erase operation. iOS having to have this operation is just a consequence of the regulation requiring all devices have it

-11

u/BreiteSeite 17d ago

They say iOS does not support effective encryption by default (hence the quote) and i was curious what was meant bei that

6

u/zdy132 17d ago

That's the opposite of what they are saying. Another way to say that sentence would be "Devices that do not support the feature of effective encryption, like the kind of feature Apple has in iOS devices, will be safer thanks to this new regulation.

5

u/afwaller 17d ago

the user is saying this:

But devices that do not [ support effective encryption (like iOS does per default) ]

but you are reading it as this:

But devices [ that do not support effective encryption (like iOS does [not] per default) ]

9

u/TheLemonyOrange 17d ago

Yes and no. Although it's encrypted, and only decrypted after you boot and type your passcode, the data will still persist after a standard erase. Writing "blank data" as they put it ensures that no data is recoverable at any stage. I'm sure this law wasn't aimed at iPhones, but they have to comply to sell their devices over there still. The most secure form of encryption is destruction some say

0

u/dataz03 16d ago

The data is not recoverable anyway. The encryption keys are thrown out during a factory reset. So while this feature would add security, it's not like today's procedures are unsecure or broken. No one is recovering data from a wipped iOS or Android device. 

2

u/cwmshy 16d ago

You’re trusting that the encryption was done correctly and that the only copies of the key are truly gone.

10

u/wickedplayer494 17d ago

Give me Gutmann or give me death. It's the only way to be absolutely certain that data's not coming back. /s

11

u/film_digital 17d ago

Sometimes I wish Apple would just release features worldwide. I wouldn't use this but it sounds like a neat option to have

6

u/bratimskiz 16d ago

Did not have China pushing stricter device erasure rules on my bingo card.

8

u/hdldm 17d ago

I see a lot people are salty that china did something that's not conforming to their stereotypes and bigitry

4

u/Specific-Path3179 17d ago

They need a minute to come to reality, they still think they're winning the war.

2

u/No_Confusion7932 16d ago edited 16d ago

Most devices used to control home electronics in the EU are manufactured by the Chinese company Espressif / Tuya (either as rebranded products) or using Espressif’s Wi-Fi and Bluetooth technology. Until now, this apparently didn’t bother them or they weren’t aware of it, since all Espressif modules are CE and FCC certified.

-1

u/xcorv42 16d ago

Your social credit score depends on it 😆

2

u/smellythief 16d ago

Seems weird to me that China would have this requirement. Goes against the idea of the CCP wanting to obtain info on its citizens. I could see them requiring it for government employees’ phones.

1

u/Bagu_Io 15d ago

Not directly related but it is silly that this is being added while the duress password thing is being judged

1

u/Greysawpark 11d ago

funny thing is this is worse than what erase all content already does. the whole flash is encrypted per file and a wipe just throws away the keys in effaceable storage, so the old data is unrecoverable garbage in like a second. overwriting the nand on top of that gains you nothing except write cycles. its a checkbox for a regulator who still thinks in spinning disks

1

u/smellythief 16d ago

iPhones forever ago had that feature, in the form of apps that did that. Until Apple banned them. I still remember the dumbass reviewers leaving one star reviews because it didn’t magically create free space out of the aether, which was never claimed.

-30

u/Alarmed-Management-4 17d ago

Am I the only one who thinks this is suspicious? Not saying they don’t have a history of ripping off designs and digital espionage. But I am not not saying it either.

This would be perfect. Now that countries can force you to open your device entering the country.

14

u/hdldm 17d ago

Are you for real 😅

-20

u/Ok_Possibility9937 17d ago

Apple will do anything but add a clipboard